Описание
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
A flaw was found in OpenStack Ironic. When the Image Service is configured for HTTP(S) Basic Authentication, Ironic may inadvertently transmit a username and password to an unintended remote host. This could lead to the disclosure of sensitive authentication credentials to an attacker who controls the unexpected host.
Дополнительная информация
Статус:
EPSS
6.3 Medium
CVSS3
Связанные уязвимости
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
OpenStack Ironic through 38.0.0 may send a username and password to an ...
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
EPSS
6.3 Medium
CVSS3